Kreatív megoldások boltja

Privacy Policy

Effective: 2026.08.14
Last modified: 2026.08.14

1. Introduction and purpose of the Notice

The purpose of this Data Processing and Privacy Notice (hereinafter: “Notice”) is to provide visitors, customers, clients, interested parties, newsletter subscribers, and other data subjects of the www.kovapapir.hu website (hereinafter: “Website”) with appropriate, transparent, and easy-to-understand information about the processing of their personal data.

The Data Controller is committed to protecting personal data and respecting the privacy of data subjects. The Data Controller processes personal data exclusively for specified, explicit, and lawful purposes, in accordance with the applicable laws.

This Notice has been prepared with particular regard to the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);

  • Act CXII of 2011 on informational self-determination and freedom of information (Info Act);

  • Act CVIII of 2001 on certain issues of electronic commerce services and information society services (E-commerce Act);

  • Act XLVIII of 2008 on the basic requirements and certain restrictions of commercial advertising activities (Advertising Act);

  • Act C of 2000 on accounting;

  • the Hungarian laws on taxation, consumer protection, and electronic commerce in force at any given time.

2. Details of the Data Controller

Name of Data Controller: Kova ‘2 Nyomtatvány Bt.

Registered office: 1149 Budapest, Nagy Lajos király útja 191.
Mailing address: 1149 Budapest, Nagy Lajos király útja 191.

Company registration number / registration number: 01-06-741763
Tax number: 21008450-2-42
Representative: Gyuris-Kovács Andrea Emese
E-mail: info@kovapapir.hu
Telephone number: +3630 647 6887
Website: www.kovapapir.hu

Hereinafter: “Data Controller”.

If the Data Controller is obliged to appoint a data protection officer, or has voluntarily appointed a data protection officer:

Name of Data Protection Officer: not applicable
Contact details: +3630 647 6887

3. Principles of data processing

During the processing of personal data, the Data Controller pays particular attention to the following principles:

Lawfulness, fairness, and transparency: personal data is processed lawfully, fairly, and in a transparent manner for the data subject.

Purpose limitation: personal data may only be processed for predefined, explicit, and lawful purposes.

Data minimisation: the Data Controller processes only personal data that is adequate, relevant, and necessary for achieving the given data processing purpose.

Accuracy: the Data Controller endeavours to ensure that the personal data it processes is accurate and, where necessary, kept up to date.

Storage limitation: personal data is retained only for as long as necessary to achieve the purpose of processing or to comply with a legal obligation.

Integrity and confidentiality: the Data Controller protects personal data through appropriate technical and organisational measures against unauthorised or unlawful processing, loss, destruction, and damage.

Accountability: the Data Controller is responsible for complying with the above principles and must be able to demonstrate such compliance.

4. DATA PROCESSING RELATED TO VISITING THE WEBSITE

4.1. Technical and log data

When visiting the Website, the IT systems serving the Website may automatically record certain technical data.

Scope of processed data

Depending on the actual technical setup, the system may process in particular:

  • IP address;

  • time of visit;

  • URL of the visited page;

  • address of the referring page;

  • browser type and version;

  • information relating to the operating system;

  • device and screen data;

  • technical log data;

  • data relating to security events.

Purpose of data processing

  • operation of the Website;

  • ensuring IT security;

  • identification and elimination of errors;

  • prevention of abuse and attacks;

  • ensuring the availability of the Website.

Legal basis

The legitimate interest of the Data Controller or a third party in the secure and proper operation of the Website pursuant to Article 6(1)(f) of the GDPR, where this legal basis is applicable to the given data processing.

Retention period

7/14/30/90 days, in accordance with the actual logging practice of the hosting provider.

5. CONTACT AND CUSTOMER COMMUNICATION

If the data subject contacts the Data Controller by e-mail, telephone, contact form, or another communication channel, the Data Controller processes the personal data necessary to respond to the enquiry.

Processed data

In particular:

  • name;

  • e-mail address;

  • telephone number;

  • company name, if provided;

  • subject of the enquiry;

  • content of the message;

  • additional data voluntarily provided by the data subject;

  • time and technical data of the communication.

Purpose of data processing

  • responding to enquiries;

  • maintaining contact;

  • providing offers;

  • handling customer requests;

  • preparing the conclusion of a contract;

  • handling complaints and other enquiries.

Legal basis

Depending on the nature of the enquiry:

  • Article 6(1)(b) of the GDPR – steps prior to entering into a contract or performance of a contract;

  • Article 6(1)(f) of the GDPR – the legitimate interest of the Data Controller in maintaining contact and handling enquiries;

  • in certain cases Article 6(1)(c) of the GDPR – compliance with a legal obligation.

Retention period

Depending on the nature of the enquiry, until the matter is closed and thereafter for the period during which potential legal claims may be enforced, unless a longer retention period is prescribed by law.

6. REQUEST FOR QUOTATION

If the Website provides the possibility to request a quotation, the Data Controller processes the data necessary for preparing the quotation and maintaining contact with the interested party.

Processed data

  • name;

  • company name;

  • e-mail address;

  • telephone number;

  • billing/shipping information, where necessary;

  • requested product or service;

  • quantity;

  • specification;

  • text of the quotation request;

  • additional data provided by the data subject.

Purpose

Preparing a quotation, maintaining contact, and preparing a possible later contract.

Legal basis

Article 6(1)(b) of the GDPR.

7. WEBSHOP PURCHASE / ORDER

Processed data

During the order process, the Data Controller may process in particular the following data:

  • customer’s name;

  • company name;

  • e-mail address;

  • telephone number;

  • billing name;

  • billing address;

  • tax number, where necessary;

  • shipping name and address;

  • ordered products;

  • quantities;

  • purchase price;

  • date and time of the order;

  • order ID;

  • selected payment method;

  • selected shipping method;

  • comment added to the order;

  • communication related to the fulfilment of the order.

  • IP address

Purpose of data processing

  • processing the order;

  • conclusion and performance of the sales contract;

  • handover/delivery of the product;

  • handling payment;

  • maintaining contact with the customer;

  • invoicing;

  • handling warranty and guarantee matters;

  • handling consumer complaints.

Legal basis

In the case of data processing necessary for the conclusion and performance of a contract, Article 6(1)(b) of the GDPR.

In the case of data processing related to invoicing, accounting, taxation, and other mandatory records, Article 6(1)(c) of the GDPR.

8. INVOICING AND ACCOUNTING

Processed data

  • billing name;

  • billing address;

  • tax number, if applicable;

  • purchased product or service;

  • consideration;

  • date of invoice;

  • date of performance;

  • payment data;

  • other mandatory accounting data.

Purpose of data processing

Issuing invoices and fulfilling accounting and tax obligations.

Legal basis

Article 6(1)(c) of the GDPR – compliance with a legal obligation applicable to the Data Controller.

Retention period

The retention period prescribed by accounting and tax legislation.

9. SHIPPING

If the Data Controller uses an external courier or logistics service provider, it may forward the personal data necessary for fulfilling the order to the service provider.

Forwarded data

Typically:

  • recipient’s name;

  • shipping address;

  • telephone number;

  • e-mail address;

  • parcel ID;

  • cash-on-delivery amount, if applicable.

Purpose

Delivery of the ordered product and notification of the recipient.

Recipient

Shipping service provider: Packli Logistics Kft
Registered office: Budapest, Lajos u. 126-130, 1036
Website: packli.hu

Shipping service provider: Magyar Posta Zrt.
Registered office: 1138 Budapest, Dunavirág utca 2-6.
Website: https://www.posta.hu/fooldal

10. ONLINE PAYMENT

In the case of online bank card payment, the Data Controller may forward the data necessary for processing the payment to the applied payment service provider.

Payment service provider: SimplePay

As a general rule, the Data Controller does not become aware of and does not store the customer’s full bank card data if the payment process is handled directly by the payment service provider’s system.

The payment service provider’s own data processing is governed by its own privacy notice.

11. NEWSLETTER AND DIRECT MARKETING

The Data Controller may send electronic messages for marketing and advertising purposes based on the data subject’s prior consent.

Processed data

  • name, if provided;

  • e-mail address;

  • time of subscription;

  • fact of consent and data necessary to verify it;

  • time of unsubscribe.

Purpose

  • sending newsletters;

  • presenting products and services;

  • communicating promotions and offers;

  • marketing communication.

Legal basis

The consent of the data subject, Article 6(1)(a) of the GDPR.

Consent may be withdrawn at any time without giving reasons.

The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Unsubscribe

The data subject may withdraw their consent through the unsubscribe option provided in every electronic message sent for marketing purposes, or by sending a request to the Data Controller.

12. COMPLAINT HANDLING

The Data Controller handles consumer or customer complaints received by it based on the applicable laws.

Processed data

  • complainant’s name;

  • contact details;

  • content of the complaint;

  • order or billing data;

  • documents attached to the complaint;

  • data relating to the investigation of the case;

  • response and related communication.

Purpose

Investigating, responding to, and documenting complaints, as well as complying with legal obligations.

Legal basis

Article 6(1)(c) of the GDPR, where data processing is prescribed by law.

13. COOKIES AND SIMILAR TECHNOLOGIES

The Website may use cookies and similar technologies for the purpose of proper operation, improving the user experience, statistical analysis, and – where applicable – marketing activity.

13.1. What is a cookie?

A cookie is a small data file that the Website or one of its service providers may place on, or read from, the user’s device.

13.2. Strictly necessary cookies

These cookies are necessary for the basic operation of the Website.

These may include, for example:

  • maintaining the session;

  • operating the shopping cart;

  • security functions;

  • remembering cookie settings;

  • load balancing.

13.3. Functional cookies

These support the operation of the Website’s convenience functions, for example by remembering the user’s previous settings.

13.4. Statistical/analytical cookies

If the Website uses such a service, these allow the Data Controller to receive information about the use of the Website.

Google Analytics: YES
Google Tag Manager: YES
Microsoft Clarity: YES
other: ?

13.5. Marketing cookies

With the help of marketing cookies, advertisements tailored to the interests of Website visitors may appear.

Meta/Facebook Pixel: YES
Google Ads: YES
TikTok Pixel: YES
other: ?

Cookies and technologies requiring consent may only be activated after the data subject has given appropriate consent.

The user may withdraw or modify their consent in the same simple manner as they gave it.

14. SOCIAL MEDIA AND EXTERNAL SERVICES

If the Website uses elements connected to social media services, data processing may also take place in the systems of the given service provider.

Such service providers may include:

  • Meta Platforms / Facebook;

  • Instagram;

  • Google / YouTube;

  • LinkedIn;

  • TikTok;

  • other service providers.

In certain cases, the individual service providers may act as independent data controllers, while in other cases they may act as joint controllers together with the Data Controller.

The data processing activity of the given service provider is governed by its own privacy notice.

15. PROCESSORS AND RECIPIENTS

The Data Controller may use external service providers for its operation.

Processors may process personal data exclusively based on the instructions of the Data Controller and the appropriate contract concluded with them, for the purpose defined therein.

Hosting provider

Name: InfoNetfort Kft.
Registered office: 7900 Szigetvár, Szent István lakótelep 17.
Task: hosting and server operation.

Website operator / developer

Name: InfoNetfort Kft.
Registered office: 7900 Szigetvár, Szent István lakótelep 17.
Task: technical operation, maintenance.

Accountant

Name: [TO BE COMPLETED]
Registered office: [TO BE COMPLETED]
Task: accounting and bookkeeping services.

Invoicing service provider

Name: PROVIMAX
Task: paper-based invoicing

Courier/logistics service provider

Name: Magyar Posta Zrt.
Task: delivery of parcels.

Name: Packli Logistics Kft
Task: preparation of parcels for courier service.

Payment service provider

Name: SimplePay Zrt.
Task: processing online payments.

Newsletter service provider

Name: MailerLite
Task: handling and sending electronic newsletters.

16. DATA TRANSFER TO THIRD COUNTRIES

The Data Controller endeavours to process personal data primarily within the European Economic Area.

However, the use of certain IT, analytical, social media, newsletter sending, or other service providers may result in personal data being transferred to a third country outside the European Economic Area.

Such data transfer may only take place if the conditions set out in Chapter V of the GDPR are met.

Depending on the given service provider, the applicable safeguard may in particular be:

  • an adequacy decision of the European Commission;

  • an appropriate data transfer framework;

  • Standard Contractual Clauses (SCC);

  • or another data transfer mechanism permitted by the GDPR.

17. AUTOMATED DECISION-MAKING AND PROFILING

As a general rule, the Data Controller does not apply decision-making based solely on automated processing, including profiling, that would produce legal effects concerning the data subject or similarly significantly affect them.

18. MANDATORY OR VOLUNTARY NATURE OF DATA PROVISION

If data processing is necessary for the performance of a contract, the provision of certain personal data is a condition for concluding or performing the contract.

If the data marked as mandatory is not provided, the Data Controller may not be able to:

  • fulfil the order;

  • deliver the product;

  • issue an invoice;

  • prepare the quotation;

  • or properly fulfil the data subject’s request.

Consent to data processing for marketing purposes is voluntary, and refusal to give such consent may not be a condition for using a service for which marketing data processing is not necessary.

19. DATA SECURITY

The Data Controller applies technical and organisational measures proportionate to the risk associated with the personal data processed.

Depending on the specific IT environment, these may include in particular:

  • restriction of access rights;

  • appropriate password management;

  • encrypted data transmission;

  • use of HTTPS;

  • regular backups;

  • virus and malware protection;

  • regular software updates;

  • logging;

  • monitoring of access;

  • appropriate information provided to employees;

  • appropriate contractual obligations undertaken by processors.

The Data Controller makes every effort to ensure that unauthorised persons cannot access, unlawfully modify, forward, disclose, delete, or destroy personal data.

20. PERSONAL DATA BREACHES

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored, or otherwise processed.

The Data Controller handles and documents personal data breaches in accordance with the provisions of the GDPR.

If the breach is likely to result in a risk to the rights and freedoms of natural persons, the Data Controller notifies the competent supervisory authority under the conditions specified by law.

In the case of high risk, the Data Controller also informs the data subject appropriately, unless an exception under the GDPR applies.

21. RIGHTS OF DATA SUBJECTS

Depending on the circumstances and legal basis of the processing, the data subject may have the following rights under the GDPR.

21.1. Right to information

The data subject has the right to receive clear, transparent, and understandable information about the processing of their personal data.

21.2. Right of access

The data subject has the right to obtain confirmation as to whether their personal data is being processed, and if so, the right to access their personal data and the related information specified by the GDPR.

21.3. Right to rectification

The data subject may request the correction of inaccurate personal data concerning them and – taking into account the purpose of the processing – the completion of incomplete data.

21.4. Right to erasure

In the cases specified by the GDPR, the data subject may request the deletion of their personal data.

The right to erasure is not unlimited. For example, the Data Controller may refuse deletion if processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

21.5. Right to restriction of processing

If the conditions specified in the GDPR are met, the data subject may request the restriction of the processing of their personal data.

21.6. Right to data portability

Where processing is based on consent or on a contract and is carried out by automated means, the data subject may, under the conditions of the GDPR, have the right to receive the personal data they have provided to the Data Controller in a structured, commonly used, machine-readable format, and may request the transfer of such data to another controller.

21.7. Right to object

Where processing is based on Article 6(1)(e) or (f) of the GDPR, the data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data.

The data subject may object at any time to processing for direct marketing purposes.

21.8. Withdrawal of consent

Where processing is based on consent, the data subject may withdraw their consent at any time.

The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

21.9. Rights related to automated decision-making

Under the conditions set out in Article 22 of the GDPR, the data subject has the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them.

22. FULFILMENT OF DATA SUBJECT REQUESTS

The data subject may submit their data protection request using the following contact details:

E-mail: info@kovapapir.hu
Postal address: 1149 Budapest, Nagy Lajos király útja 191.

The Data Controller informs the data subject of the measures taken following the request without undue delay, as a general rule within one month of receipt of the request.

The deadline may be extended by a further two months under the conditions specified in the GDPR, in particular taking into account the complexity of the request and the number of requests.

The Data Controller may request additional information necessary to confirm the identity of the applicant if it has reasonable doubts concerning the identity of the person submitting the request.

23. REMEDIES

If the data subject believes that the processing of their personal data violates data protection laws, they have the right to lodge a complaint with the competent supervisory authority.

In Hungary, the supervisory authority is:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered office: 1055 Budapest, Falk Miksa utca 9–11.
Mailing address: 1363 Budapest, Pf. 9.
Telephone: +36 (1) 391-1400
Website: www.naih.hu
E-mail: ugyfelszolgalat@naih.hu

The data subject is also entitled to turn to the courts under the conditions specified in the GDPR and the applicable Hungarian laws.

The Data Controller asks data subjects, where possible, to contact it before initiating authority or court proceedings so that it may attempt to resolve the issue directly. This, however, does not affect or restrict the data subject’s rights to legal remedy.

24. PERSONAL DATA OF CHILDREN

As a general rule, the Website and the services of the Data Controller are not intended for children.

The Data Controller does not intentionally seek to collect personal data of children, unless the given service or data processing specifically requires this and the legal conditions for it are met.

If the Data Controller becomes aware that it is processing the personal data of a child without an appropriate legal basis, it will take the necessary measures.

25. SOURCE OF PERSONAL DATA

As a general rule, the Data Controller obtains personal data directly from the data subject.

In certain cases, personal data may originate from:

  • the business represented by the data subject;

  • a contractual partner;

  • a shipping or payment service provider;

  • a publicly available source;

  • or another lawful data source.

If the Data Controller does not obtain personal data directly from the data subject, the rules of Article 14 of the GDPR also apply to the given data processing.

26. DATA RETENTION PRINCIPLES

The Data Controller does not retain personal data indefinitely.

When determining the data retention period, it takes into account:

  • the purpose of the processing;

  • the duration of the contract;

  • statutory retention obligations;

  • limitation periods;

  • the possibility of enforcing potential legal claims;

  • data security and fraud prevention requirements.

After the purpose of processing ceases and the mandatory retention period expires, the Data Controller deletes the personal data or, where appropriate, irreversibly anonymises it.

27. PROCESSING BASED ON LEGITIMATE INTEREST

If the Data Controller bases data processing on legitimate interest under Article 6(1)(f) of the GDPR, before starting the processing it assesses:

  1. the legitimate interest pursued by the Data Controller or a third party;

  2. the necessity of the processing;

  3. the interests, fundamental rights, and freedoms of the data subject;

  4. the reasonable expectations of the data subject;

  5. the possible impact of the processing on the data subject;

  6. the applicable safeguards.

The data subject has the right to request information about the legitimate interest behind the given data processing.

28. MODIFICATION OF THE NOTICE

The Data Controller is entitled to modify this Notice, in particular if:

  • the operation of the Website changes;

  • a new data processing process begins;

  • a new service provider or processor is involved;

  • the applied technology changes;

  • there is a change in legislation;

  • a change in authority or court practice justifies it.

The Notice in force at any given time is available on the Website.

In the event of a material change, the Data Controller may – where necessary and possible – draw the attention of data subjects to the change separately in an appropriate manner.

29. CONTACT

Questions and requests relating to the processing of personal data, this Notice, or the exercise of data subject rights may be sent to the following contact details:

Kova ‘2 Nyomtatvány Bt.

Registered office: 1149 Budapest, Nagy Lajos király útja 191.
Mailing address: 1149 Budapest, Nagy Lajos király útja 191.
E-mail: info@kovapapir.hu
Telephone: +3630 647 6887
Website: www.kovapapir.hu

Effective date: 2026.08.14.

Document version: 1.0